A Remote Code Execution (RCE) vulnerability exists in Croogo 3.0.2via admin/file-manager/attachments, which lets a malicoius user upload a web shell script.
| Software | From | Fixed in |
|---|---|---|
| croogo / croogo | 3.0.2 | 3.0.2.x |
croogo / croogo
|
- | 3.0.2.x |